CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
121 | CVE-1999-0121 | Candidate | Buffer overflow in dtaction command gives root access. | Proposed (19990617) | ACCEPT(2) Dik, Northcutt | MODIFY(3) Baker, Frech, Prosser | REVIEWING(1) Christey | Frech> Reference: XF:dtaction-bo | Reference: XF:sun-dtaction | Prosser> Buffer overflow also affects /usr/dt/bin/dtaction in libDtSvc.a | library in AIX 4.x, but reference for this Sun vulnerability should | only reflect the Sun Bulletin or the CIAC I-032 version of the Sun | Bulletin | Christey> This is the Same Codebase as CVE-1999-0089, so the two entries | should be merged. | Frech> Replace sun-dtaction(732) with dtaction-bo(879) | Baker> Merge with 1999-0089 | View |
3886 | CVE-2001-1082 | Candidate | Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack. | Proposed (20020131) | ACCEPT(4) Armstrong, Baker, Cole, Green | MODIFY(1) Christey | NOOP(2) Foat, Wall | REJECT(1) Frech | Frech> Reference no longer exists, and has no title for cross | reference. | CHANGE> [Frech changed vote from REVIEWING to REJECT] | Frech> Dead reference; will reconsider revote if valid reference | presented. | Christey> MISC:http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0009.html | View |
525 | CVE-1999-0528 | Candidate | A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of. | Proposed (19990726) | ACCEPT(3) Baker, Meunier, Northcutt | MODIFY(1) Frech | Frech> possibly XF:nisd-dns-fwd-check | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:firewall-external-packet-forwarding(8372) | View |
611 | CVE-1999-0629 | Candidate | The ident/identd service is running. | Proposed (19990721) | ACCEPT(2) Baker, Ozancin | MODIFY(1) Frech | NOOP(2) Christey, Wall | REJECT(1) Northcutt | Frech> possibly XF:identd? | Christey> XF:ident-users(318) ? | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:identd-vuln(61) | XF:ident-users(318) | View |
193 | CVE-1999-0193 | Candidate | Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option. | Proposed (19990714) | ACCEPT(5) Bishop, Cole, Northcutt, Ozancin, Shostack | MODIFY(2) Baker, Blake | NOOP(4) Armstrong, Frech, Landfield, Wall | REVIEWING(2) Christey, Levy | Frech> possibly XF:ascend-kill | I can"t find a reference that lists both routers in the same reference. | Wall> Comment: There is a reference about the zero length TCP option in BugTraq on | Feb 5, 1999 | and it mentions Cisco, but not directly Ascend or 3Com. CIAC Advisory I-038 | mentions | vulnerabilities in Ascend, but does not mention TCP. CIAC Advisory I-052 | mentions | 3Com vulnerabilities, but not TCP. Too confusing withour better references. | Landfield> What are the references for this ? I cannot find a means to check it out. | CHANGE> [Frech changed vote from REVIEWING to NOOP] | Frech> Cannot reconcile to our database without further references. | Blake> I"m with Andre. I only remember and can find reference to the Ascend | issue. Do we have a refernce to the 3Coms? If not, that should be | removed from the description. | Baker> http://xforce.iss.net/static/614.php Misc Defensive Info | http://www.securityfocus.com/archive/1/5682 Misc Offensive Info | http://www.securityfocus.com/archive/1/5647 Misc Defensive Info | http://www.securityfocus.com/archive/1/5640 Misc Defensive Info | CHANGE> [Armstrong changed vote from REVIEWING to NOOP] | View |
Page 224 of 20943, showing 5 records out of 104715 total, starting on record 1116, ending on 1120